Scenario playbooks
End-to-end operator narratives
Not single tools — full stories with intent, actions, expected results, pitfalls, and remediation. Run them in authorized labs and on networks you own.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Compromised IoT camera on home Wi-Fi
Discover a camera, prove weak auth/RTSP exposure on hardware you own, contain it, and harden the LAN so a cam cannot reach trusted devices.
Exposed NAS share on the LAN
Find an open or weakly shared NAS/folder, prove data exposure without bulk theft, and lock down shares + network path.
Web foothold → host privesc (lab)
Full narrative on an authorized lab box: map web app, gain RCE/file foothold, escalate on Linux, document each stage with fixes.
Close accidental WAN exposure
Discover what the internet can see on your public IP, shut down risky forwards, and replace remote access with VPN.
Purple loop: noisy scan vs detection
Run a controlled Nmap/Hydra burst in lab, then find yourself in logs and write a detection note.
Password and auth lab narrative
From weak hash capture in lab to cracking methodology to online auth testing — with reporting that does not encourage reckless spraying.